AlmaLinux 9.6 [TuxCare] 安全更新:kernel / kernel-abi-stablelists / kernel-core / 等多个漏洞 (ALMALINUX9.6:CLSA-2026:1789986443)

high Nessus 插件 ID 352548

简介

AlmaLinux 主机缺少一个或多个安全更新。

描述

AlmaLinux 9.6 主机上存在安装的程序包,该程序包受到 TuxCare ALMALINUX9.6:CLSA-2026:2026:1789986443公告中提及的多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:net: hns3: add vlan list lock to protect vlan list When adding port base VLAN, vf VLAN need to remove from HW and modify the vlan state in vf VLAN list as false. If the periodicity task is freeing the same node, it may cause use after free error. This patch adds a vlan list lock to protect the vlan list. (CVE-2022-49182)

- 已修复 Linux 内核中的下列漏洞:tracing: Fix reading strings from synthetic events The follow commands caused a crash: # cd /sys/kernel/tracing # echo 's:open char file[]' > dynamic_events # echo 'hist:keys=common_pid:file=filename:onchange($file).trace(open,$file)' > events/syscalls/sys_enter_openat/trigger' # echo 1 > events/synthetic/open/enable BOOM! The problem is that the synthetic event field char file[] will read the value given to it as a string without any memory checks to make sure the address is valid. The above example will pass in the user space address and the sythetic event code will happily call strlen() on it and then strscpy() where either one will cause an oops when accessing user space addresses. Use the helper functions from trace_kprobe and trace_eprobe that can read strings safely (and actually succeed when the address is from user space and the memory is mapped in). Now the above can show: packagekitd-1721 [000] ...2. 104.597170: open:
file=/usr/lib/rpm/fileattrs/cmake.attr in:imjournal-978 [006] ...2. 104.599642: open:
file=/var/lib/rsyslog/imjournal.state.tmp packagekitd-1721 [000] ...2. 104.626308: open:
file=/usr/lib/rpm/fileattrs/debuginfo.attr (CVE-2022-50255)

- 已修复 Linux 内核中的下列漏洞:ipc: fix memleak if msg_init_ns failed in create_ipc_ns Percpu memory allocation may failed during create_ipc_ns however this fail is not handled properly since ipc sysctls and mq sysctls is not released properly. Fix this by release these two resource when failure. Here is the kmemleak stack when percpu failed: unreferenced object 0xffff88819de2a600 (size 512): comm shmem_2nstest, pid 120711, jiffies 4300542254 hex dump (first 32 bytes): 60 aa 9d 84 ff ff ff ff fc 18 48 b2 84 88 ff ff `.........H..... 04 00 00 00 a4 01 00 00 20 e4 56 81 ff ff ff ff ........
.V..... backtrace (crc be7cba35): [<ffffffff81b43f83>] __kmalloc_node_track_caller_noprof+0x333/0x420 [<ffffffff81a52e56>] kmemdup_noprof+0x26/0x50 [<ffffffff821b2f37>] setup_mq_sysctls+0x57/0x1d0 [<ffffffff821b29cc>] copy_ipcs+0x29c/0x3b0 [<ffffffff815d6a10>] create_new_namespaces+0x1d0/0x920 [<ffffffff815d7449>] copy_namespaces+0x2e9/0x3e0 [<ffffffff815458f3>] copy_process+0x29f3/0x7ff0 [<ffffffff8154b080>] kernel_clone+0xc0/0x650 [<ffffffff8154b6b1>] __do_sys_clone+0xa1/0xe0 [<ffffffff843df8ff>] do_syscall_64+0xbf/0x1c0 [<ffffffff846000b0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53 (CVE-2024-53175)

- 已修复 Linux 内核中的下列漏洞:net/mlx5: HWS, change error flow on matcher disconnect Currently, when firmware failure occurs during matcher disconnect flow, the error flow of the function reconnects the matcher back and returns an error, which continues running the calling function and eventually frees the matcher that is being disconnected. This leads to a case where we have a freed matcher on the matchers list, which in turn leads to use-after-free and eventual crash. This patch fixes that by not trying to reconnect the matcher back when some FW command fails during disconnect. Note that we're dealing here with FW error. We can't overcome this problem. This might lead to bad steering state (e.g. wrong connection between matchers), and will also lead to resource leakage, as it is the case with any other error handling during resource destruction. However, the goal here is to allow the driver to continue and not crash the machine with use-after-free error. (CVE-2025-21751)

- 已修复 Linux 内核中的下列漏洞:wifi: ath12k: Avoid memory leak while enabling statistics Driver uses monitor destination rings for extended statistics mode and standalone monitor mode. In extended statistics mode, TLVs are parsed from the buffer received from the monitor destination ring and assigned to the ppdu_info structure to update per-packet statistics. In standalone monitor mode, along with per-packet statistics, the packet data (payload) is captured, and the driver updates per MSDU to mac80211. When the AP interface is enabled, only extended statistics mode is activated. As part of enabling monitor rings for collecting statistics, the driver subscribes to HAL_RX_MPDU_START TLV in the filter configuration. This TLV is received from the monitor destination ring, and kzalloc for the mon_mpdu object occurs, which is not freed, leading to a memory leak. The kzalloc for the mon_mpdu object is only required while enabling the standalone monitor interface. This causes a memory leak while enabling extended statistics mode in the driver. Fix this memory leak by removing the kzalloc for the mon_mpdu object in the HAL_RX_MPDU_START TLV handling. Additionally, remove the standalone monitor mode handlings in the HAL_MON_BUF_ADDR and HAL_RX_MSDU_END TLVs. These TLV tags will be handled properly when enabling standalone monitor mode in the future. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1 Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3 (CVE-2025-37743)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 ALMALINUX9.6:CLSA-2026:1789986443 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1789986443

http://www.nessus.org/u?8e332f8e

插件详情

严重性: High

ID: 352548

文件名: tuxcare_alma_linux_9.6_CLSA-2026-1789986443.nasl

版本: 1.1

类型: Local

发布时间: 2026/9/30

最近更新时间: 2026/9/30

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.7

百分位: 99.06

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.3

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-45996

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/9/21

漏洞发布日期: 2024/12/27

参考资料信息

CVE: CVE-2022-49182, CVE-2022-50255, CVE-2024-53175, CVE-2024-57857, CVE-2025-21751, CVE-2025-22015, CVE-2025-37743, CVE-2025-38364, CVE-2025-38588, CVE-2025-38593, CVE-2025-39946, CVE-2025-39977, CVE-2025-40016, CVE-2025-40105, CVE-2025-40173, CVE-2025-40231, CVE-2025-68192, CVE-2025-68363, CVE-2025-68785, CVE-2025-68816, CVE-2026-23142, CVE-2026-23166, CVE-2026-23262, CVE-2026-23327, CVE-2026-23343, CVE-2026-23386, CVE-2026-23466, CVE-2026-31407, CVE-2026-31440, CVE-2026-31446, CVE-2026-31448, CVE-2026-31449, CVE-2026-31450, CVE-2026-31458, CVE-2026-31491, CVE-2026-31505, CVE-2026-31557, CVE-2026-31589, CVE-2026-31591, CVE-2026-31700, CVE-2026-43025, CVE-2026-43048, CVE-2026-43059, CVE-2026-43091, CVE-2026-43092, CVE-2026-43125, CVE-2026-43134, CVE-2026-43253, CVE-2026-43437, CVE-2026-43468, CVE-2026-45963, CVE-2026-45996, CVE-2026-46197, CVE-2026-52910, CVE-2026-52946, CVE-2026-52961, CVE-2026-53133, CVE-2026-53186, CVE-2026-53250, CVE-2026-53253, CVE-2026-53281, CVE-2026-53324, CVE-2026-53356, CVE-2026-64173, CVE-2026-64210, CVE-2026-64213, CVE-2026-64275, CVE-2026-64570, CVE-2026-68090, CVE-2026-68091, CVE-2026-68093, CVE-2026-68108, CVE-2026-68113, CVE-2026-68115, CVE-2026-68123, CVE-2026-68129, CVE-2026-68142, CVE-2026-68145, CVE-2026-68155, CVE-2026-68156, CVE-2026-68159, CVE-2026-68160, CVE-2026-68162, CVE-2026-68165, CVE-2026-68169, CVE-2026-68188, CVE-2026-68202, CVE-2026-68206, CVE-2026-68234, CVE-2026-68243, CVE-2026-68245, CVE-2026-68246, CVE-2026-68248, CVE-2026-68253, CVE-2026-68257, CVE-2026-68258, CVE-2026-68264, CVE-2026-68269, CVE-2026-68271, CVE-2026-68276, CVE-2026-68277, CVE-2026-68288, CVE-2026-68294, CVE-2026-68296, CVE-2026-68307, CVE-2026-68343, CVE-2026-68348, CVE-2026-68362, CVE-2026-68376, CVE-2026-68377, CVE-2026-68391, CVE-2026-68393, CVE-2026-68394, CVE-2026-68398, CVE-2026-68419, CVE-2026-68432, CVE-2026-68436, CVE-2026-68446, CVE-2026-68448, CVE-2026-72472, CVE-2026-74565

CLSA: 2026:1789986443